Change Data Capture Pipeline  ·  View 09 of 21  ·  Structure

Integration Surface

Three interfaces in, three out, and exactly one contract in each direction.

Editable source SVG draw.io All views
Sources (read-only) PostgreSQL · orders 62 tables PostgreSQL · billing 44 tables PostgreSQL · identity 31 tables CDC Platform Capture plane Change log 7-day retention Changelog archive 13 months Projection plane Control plane Destinations and dependencies BigQuery mirror + changelog Search index Cache and webhook fan-out 14 partners WAL WAL decode WAL · masked MERGE micro-batch upsert async events Integration Surface — Sources, Platform, Destinations External / third party Interface / broker Queue / topic Data store Application we own Security / platform synchronous event / async Three source interfaces in, three sinks out, one contract each way. The snapshot read path and heartbeat probe are internal to capture (view 14). v 1.0 · owner Data Platform Architecture · date 2026-10

The two contracts

  • Inbound: read the write-ahead log through one replication slot per database, under a read-only replication identity.
  • Outbound: apply idempotently, keyed on (primary key, log position), tolerating at-least-once delivery and out-of-order arrival (ADR-04).
  • Every sink that cannot meet the outbound contract is not a sink: it is a consumer of one.

Assumptions

  • Three source databases are shown of twelve; the identity database is capture-masked at column level.
  • The webhook fan-out serves 14 partners and is the only sink with an external delivery SLA.

Known clutter

  • The route checker reports one label-proximity warning on this view; the alternative was dropping a source interface from the catalogue, which costs the reader more.